Every morning at 6 AM, a system I built collects articles from over 30 cybersecurity RSS feeds, scores them by relevance, generates an AI-written daily brief, converts it into a podcast episode, publishes it to a website, and sends a newsletter to subscribers. The entire thing runs unattended on a Linux container that costs about $5/month to operate.
This is the story of how I built it, what I learned, and why I think every IT consultancy should be doing something similar.
The Problem
If you work in IT or cybersecurity, you know the drill. Every morning you need to check a dozen sources to understand what happened overnight. New CVEs, ransomware campaigns, vendor patches, threat actor activity - it never stops. For a small consultancy like mine, spending an hour every morning just reading the news is time that could be spent on client work.
I wanted a system that would do the reading for me and surface only what matters. Not a generic news aggregator - something tuned to the specific threats that affect my clients: small and mid-size businesses running Windows, Active Directory, Microsoft 365, and common MSP tools.
The Architecture
The pipeline has six stages, each handling a specific step:
Stage 1: Collection
A Python script using feedparser pulls from 30+ RSS feeds organized by category - vulnerability disclosures, ransomware tracking, Windows/AD security, general news, and MSP-focused sources. Each feed has a priority level (must-read vs. supplemental) and a category tag.
The full article body gets extracted using trafilatura, which handles the messy work of pulling clean text from various website layouts. Articles are stored in a SQLite database with deduplication - if the same story appears in five different feeds, we keep one record but track all the sources.
Stage 2: Scoring & Prioritization
Not every article is worth covering. The scoring system uses a keyword-based approach tuned to our client profile:
- Critical keywords (weight: 10): ransomware, zero-day, active exploitation, CISA KEV
- High keywords (weight: 5): Active Directory, Windows Server, Exchange, RMM, Patch Tuesday
- Medium keywords (weight: 3): PowerShell, Defender, Intune, VPN, backup
- Negative keywords (penalty: -3): webinar, sponsored, whitepaper, demo
Articles also get bonuses for mentioning CVE IDs (+3), appearing in multiple feeds (+5 per additional source), and coming from priority feeds (+2). The top 40 articles by score get sent to the next stage.
Stage 3: AI Brief Generation
This is where it gets interesting. The scored articles get packaged in a structured XML format and sent to Claude (using the Claude Code CLI) along with a detailed system prompt. The prompt defines the output format - sections like Critical Alerts, Vulnerability Disclosures, Ransomware & Extortion, Windows/AD Security - and gives specific instructions on tone, length, and what to prioritize.
The AI generates a 1500-2000 word brief that merges related stories, cites all sources, includes actionable recommendations (specific KB numbers, patch versions), and skips marketing fluff. One API call per day keeps costs minimal.
Stage 4: Audio Generation
The written brief gets converted to a podcast episode using Kokoro TTS, an open-source text-to-speech model that runs locally. The text goes through 11 cleanup steps before synthesis:
- Expanding acronyms on first use (CISA becomes "CISA, the Cybersecurity and Infrastructure Security Agency")
- Humanizing version numbers (24.3.4 becomes "24 dot 3 dot 4")
- Replacing lists of CVE IDs with "see show notes"
- Fixing brand pronunciations (CrowdStrike becomes "Crowd Strike")
- Adding natural pauses between sections
The result is a 5-8 minute podcast episode that sounds natural enough to listen to during a commute.
Stage 5: Publishing
A static site generator builds HTML pages for each brief - a landing page with the latest episode, individual date pages, an archive, and both RSS and podcast RSS feeds (with iTunes namespace tags for Apple Podcasts compatibility). Everything gets deployed via SCP to an Apache server running on an LXC container.
Stage 6: Newsletter
Finally, the brief gets sent to subscribers via Listmonk, a self-hosted newsletter platform. Subscribers get a formatted email with the brief content and a link to the audio version.
The Infrastructure
The entire stack runs on commodity hardware:
- LXC 702 - Apache web server hosting the static site (Cloudflare Tunnel for HTTPS)
- LXC 711 - Listmonk newsletter server
- Windows Task Scheduler - Triggers the pipeline at 6:00 AM daily
- Kokoro TTS - Runs locally, no cloud API needed for audio
Total monthly cost: Claude API usage (a few cents per day for one Haiku call) plus the electricity to run two lightweight containers. Call it $5/month.
What I Learned
Deduplication is harder than collection
Getting RSS feeds is easy. Figuring out that five feeds all reported the same CVE-2026-XXXX from different angles, and merging them into one coherent story with all sources cited, is the real engineering challenge. Title similarity matching and URL dedup catch most cases, but edge cases are endless.
TTS text cleanup is 80% of the audio work
Kokoro produces great audio. The challenge is feeding it text that sounds natural when spoken. Numbers, acronyms, version strings, and URLs all need special handling. The 11-step cleanup pipeline took longer to build than the entire scoring system.
One good AI prompt beats ten mediocre ones
I spent time crafting a single, detailed system prompt rather than chaining multiple AI calls. The prompt specifies exact output format, tone guidelines, content rules (merge duplicates, cite sources, include actionable steps), and negative rules (no marketing, no hedging). One well-engineered prompt call per day keeps costs near zero and quality high.
Why This Matters for IT Consultancies
If you run an MSP or IT consultancy, you should be publishing content like this. Here's why:
- Authority building - Clients see you as the expert who knows what's happening in security today
- Lead generation - Newsletter subscribers are warm leads who already trust your expertise
- Client communication - Forward the brief to clients when it mentions a threat relevant to their environment
- SEO - Daily content with specific, searchable terms (CVE IDs, product names, attack techniques) drives organic traffic
The pipeline is fully automated. Once built, it requires zero daily effort. The only ongoing cost is a few dollars in infrastructure.
Try It Yourself
The Cyber Threat Brief publishes every morning at 6 AM Eastern. You can read it on the web, listen to the podcast, or subscribe for email delivery. We also publish an AI Business Brief covering AI tools and trends for business leaders.
If you're interested in building something similar for your business, or if you need help with cybersecurity, secure AI adoption, or AI development enablement, let's talk.